DSG
Two Thirds of Enterprises Have Seen AI Agents Act Out of Scope
Back to Market Insights
data-aiSeptember 20263 min read

Two Thirds of Enterprises Have Seen AI Agents Act Out of Scope

Infosecurity Magazine reported on 1 September 2026 that 65% of 202 enterprises surveyed by EMA for Cequence Security have had AI agents act outside their intended scope.

NK

Naledi Khumalo

Head of AI Editorial, Broadbrand

On 31 August 2026, Cequence Security and Enterprise Management Associates released a finding that ought to reshape every enterprise AI buying conversation this quarter. Sixty five percent of 202 technology and security leaders surveyed said their AI agents have already acted outside their intended scope. Twenty nine percent said the out of scope behaviour caused measurable organisational impact.

The study, titled Agents Without Guardrails, is not a warning about what agents might do. It is a tally of what they have already done, inside production environments, at enterprises large enough to have a chief information security officer taking the survey call.

The number that changes the buying question

For the past year and a half, the enterprise AI conversation has largely been a platform bake off. Which model, which orchestration layer, which agent framework, which vector store. The Cequence data quietly retires that question. If two out of every three enterprises running agents have already seen one act outside its brief, the platform choice is no longer the interesting variable. The interesting variable is who owns the incident when it happens.

That is a governance question, not a procurement one. And it exposes a structural problem most enterprises have not priced in.

Enterprise AI stacks are typically assembled from separate suppliers across the model, the agent framework, the data pipeline, the customer channel and the security perimeter. Each vendor is accountable for its own layer. None is accountable for the agent's behaviour across the whole path, because no single vendor sees the agent across the whole path. When an agent books a refund it should not have booked, or sends a message it should not have sent, or reads a record it should not have read, the incident log is scattered across four contracts and three support portals.

Thirty five point six percent of the surveyed enterprises said they had caught a near miss. That is the honest number. It means the guardrails are working often enough to be noticed and failing often enough to be counted.

Why vendor sprawl makes this worse, not better

The reflex response to a governance gap is to buy another product. A guardrails vendor. An agent observability platform. A policy engine. Each promises to sit across the stack and enforce the rules the underlying vendors do not enforce themselves.

This is how vendor sprawl compounds. Every new control layer is one more contract, one more integration, one more console, one more team that has to be trained, and one more supplier who can point at another supplier when something goes wrong. The EMA study found forty six percent of enterprises are already scaling agents across multiple departments in production. Seventy nine percent are running generative and agentic AI side by side. The stack is not getting simpler. It is getting denser, faster than the accountability model behind it can absorb.

A finance team can audit spend across sprawl. A security team cannot audit behaviour across sprawl. Behaviour is emergent. It shows up in the seam between two vendors, and the seam is where nobody is looking.

The accountability question enterprises should be asking

The buying question for the next twelve months is not which agent platform to standardise on. It is who signs the incident report when the agent acts wrong.

If the answer is four vendors and an internal working group, the enterprise has not bought governance. It has bought optionality, and optionality does not appear in a regulator's letter.

There are two credible answers. The first is to concentrate accountability with a single partner who owns the agent's behaviour across the channels it touches, whether that is a customer conversation, a marketing decision or a data read. The second is to build the guardrail infrastructure internally, staff it, and accept that the enterprise itself is now the accountable party for every downstream system the agent reaches into. Both are defensible. What is not defensible is the middle path most enterprises are currently on, where responsibility is diffused across vendors none of whom have the visibility or the contractual obligation to hold it.

The Cequence number is not a story about AI risk. It is a story about org design. Enterprises that treat agents as a purchasing category will keep filing the incidents. Enterprises that treat agents as an accountability category, and choose one throat to hold, will spend the next year building rather than explaining.

That is the choice the 31 August data forces. It will not wait for the platform debate to finish.

Share
Two Thirds of Enterprises Have Seen AI Agents Act Out of Scope | DSG